diff options
Diffstat (limited to 'hosts/cirrus')
| -rw-r--r-- | hosts/cirrus/configuration.nix | 7 | ||||
| -rw-r--r-- | hosts/cirrus/default.nix | 8 | ||||
| -rw-r--r-- | hosts/cirrus/wireguard-server.nix | 43 |
3 files changed, 52 insertions, 6 deletions
diff --git a/hosts/cirrus/configuration.nix b/hosts/cirrus/configuration.nix index 0054a64..d26af82 100644 --- a/hosts/cirrus/configuration.nix +++ b/hosts/cirrus/configuration.nix @@ -5,11 +5,6 @@ { config, pkgs, ... }: { - imports = - [ # Include the results of the hardware scan. - ./hardware-configuration.nix - ]; - # Use the GRUB 2 boot loader. boot.loader.grub.enable = true; boot.loader.grub.version = 2; @@ -27,7 +22,7 @@ networks."uplink" = { matchConfig = { Name = "enp1s0"; }; networkConfig = { - DHCP="yes"; + DHCP="yes"; # hetzner suggests this as default }; }; }; diff --git a/hosts/cirrus/default.nix b/hosts/cirrus/default.nix new file mode 100644 index 0000000..7864357 --- /dev/null +++ b/hosts/cirrus/default.nix @@ -0,0 +1,8 @@ +{ + imports = [ + ./hardware-configuration.nix + ./configuration.nix + ./secrets.nix + ./wireguard-server.nix + ]; +} diff --git a/hosts/cirrus/wireguard-server.nix b/hosts/cirrus/wireguard-server.nix new file mode 100644 index 0000000..742912e --- /dev/null +++ b/hosts/cirrus/wireguard-server.nix @@ -0,0 +1,43 @@ +{ config, ... }: +{ + systemd.network = { + netdevs."oxalab" = { + netdevConfig = { + Kind = "wireguard"; + Name = "oxalab"; + Description = "oxa's enterprise network"; + }; + wireguardConfig = { + PrivateKeyFile = config.sops.secrets."wg/oxalab-seckey".path; + ListenPort = 51820; + # own pubkey: 5nCVC21BL+1r70OGwA4Q6Z/gcPLC3+ZF8sTurdn7N0E= + }; + wireguardPeers = [ + { + # microwave + wireguardPeerConfig = { + # nextcloud down, have to keep things in here: https://www.youtube.com/watch?v=1c6v7j1TUBI + PublicKey = "0zpfcNrmbsNwwbnDDX4SMl4BVTB0zuhGKixT9TJQoHc="; + AllowedIPs = [ "10.66.66.10/32" ]; + PersistentKeepalive = 25; + }; + } + { + # Dishwasher + wireguardPeerConfig = { + # nextcloud down, have to keep things in here: https://www.youtube.com/watch?v=1c6v7j1TUBI + PublicKey = "xrremJFIcxwR6snoTUK+mytjez60I91XE120OQGQ7gc="; + AllowedIPs = [ "10.66.66.100/32" ]; + PersistentKeepalive = 25; + }; + } + ]; + }; + networks."oxalab" = { + matchConfig.Name = "oxalab"; + networkConfig = { + Address = "10.13.37.1"; + }; + }; + }; +} |
